Junglewise Threat Intelligence

CVE-2026-46459: ICU Scandinavia Boomerang missing authentication in device receiver endpoints

CVE-2026-46459 · Severity: info · CVSS 5.3 · Published 2026-07-15

Executive brief

ICU Scandinavia Boomerang, a monitoring system used in laboratories and medical facilities to track environmental conditions like temperature and humidity, contains a security flaw in its device communication endpoints. An unauthorized person on the local network can exploit this to view sensitive facility configurations or insert false data into the sensor database. This could lead to inaccurate quality assurance records or the masking of environmental failures that might damage vaccines, blood samples, or other sensitive materials.

Technical details

ICU Scandinavia Boomerang suffers from a missing authorization vulnerability (CWE-862) within its device receiver endpoints. The application fails to validate the identity of entities connecting to these endpoints, which are intended for receiving data from environmental sensors. An unauthenticated attacker with network access to the system can read full facility configurations and inject unauthorized or fraudulent data into the sensor database. This vulnerability was coordinated by CERT Polska and is resolved in version 2.4.18.029.

Affected products

  • ICU Scandinavia Boomerang All versions prior to 2.4.18.029

Timeline

  • 2026-07-15: advisory
  • 2026-07-15: disclosed
  • 2026-07-15: patched: Fixed in version 2.4.18.029

References

Related threats